Privacy Statement
cdm-IT AI Requirements Bridge — an extension for Microsoft Dynamics 365 Business Central
This privacy statement describes how personal data is processed in connection with the software extension "cdm-IT AI Requirements Bridge" (the "App") for Microsoft Dynamics 365 Business Central ("Business Central"). It supplements the general privacy statement of our website at cdm-it.de/datenschutz, which continues to apply to visits to our website.
In short: Your data stays in your own Business Central environment — we never see it and operate no backend for it. The AI features send only the content you enter (plus technical schema metadata, never business records) to Microsoft's Azure OpenAI service, which does not use it to train models. The only data we receive ourselves is technical telemetry without any business content, and what you send us in support requests.
1. Controller and Contact
cdm-IT & Consulting Services GmbH
Gothaer Weg 12
40627 Düsseldorf, Germany
E-Mail: support@cdm-it.de
Web: cdm-it.de
("cdm-IT", "we", "us")
2. Roles: Who Is Responsible for Which Data
2.1 The App runs entirely inside the customer's own Business Central environment in the customer's Microsoft cloud tenant. All requirements, dialog contents, generated documents, attachments and audit log entries created with the App are stored exclusively in the customer's Business Central database. cdm-IT operates no backend of its own for this data and has no access to it.
2.2 For the business data processed in the App, the customer is the controller within the meaning of Art. 4(7) GDPR. Microsoft acts as the customer's processor under the customer's existing agreement with Microsoft (including the Microsoft Products and Services Data Protection Addendum). cdm-IT is not a processor for this data, because it never receives it.
2.3 cdm-IT itself processes personal data only in two narrow areas, described below: technical operational telemetry (section 6) and support communication (section 7). For these, cdm-IT is the controller.
3. Data Processed by the App Within Business Central
3.1 When using the App, the following data is created and stored in the customer's Business Central environment:
- Requirements (title, description, category, status and related fields) entered by users;
- questions, answers and assumptions from the AI-guided requirements dialog;
- generated specification documents (Markdown and PDF) and their version history;
- an activity and audit log recording who performed which action and when (user ID and timestamp);
- configuration data entered by the customer's administrator in the App setup.
3.2 This data contains personal data primarily in the form of user identifiers (the Business Central user who created or changed a record) and any personal data that users choose to enter as free text. The App does not require the entry of personal data of third parties; we recommend describing requirements without reference to identifiable individuals where possible.
3.3 This data remains in the customer's environment until the customer changes or deletes it. It is covered by the customer's own Business Central backup, retention and deletion processes. The App additionally supports Business Central retention policies for its log data, which the customer's administrator can configure in the App setup.
4. AI Functionality (Azure OpenAI via Business Central AI Resources)
4.1 The App's AI features (guided requirements dialog, document generation) use large language models provided through Microsoft-managed Azure OpenAI resources ("Business Central AI resources"). The AI features are only available after the customer's administrator has enabled the relevant Copilot capability in Business Central and, where applicable, has consented to data movement across regions in accordance with Microsoft's settings.
4.2 For each AI request, the content required for that request is transmitted to the Azure OpenAI service for processing. Depending on the feature, this includes:
- the requirement title and description;
- previous questions and the user's answers from the requirements dialog;
- previously generated documents of the same requirement (as context for consistent follow-up documents), including versions edited manually by users;
- technical schema metadata of Business Central objects linked to the requirement (object and field names, types and lengths — see section 5).
4.3 No business records are read or transmitted by the App itself. The App is designed not to access customer business data (such as customer, vendor or transaction records) for prompt building. Personal data reaches the AI service only to the extent that users have entered it as free text in requirements, answers or manually edited documents.
4.4 Processing by the Azure OpenAI service takes place within the Microsoft cloud under the customer's agreement with Microsoft. According to Microsoft's product terms for Azure OpenAI and Business Central AI resources, prompts and generated content are not used to train the underlying models and are not made available to other customers. Details, including the processing regions and Microsoft's abuse-monitoring configuration for Business Central AI resources, are described in Microsoft's documentation and the Microsoft Privacy Statement.
4.5 cdm-IT has no access to the prompts, responses or any other content of these AI requests.
5. Object Metadata Grounding
5.1 To improve the quality of questions and documents, users can link Business Central objects (for example tables or pages) to a requirement. The App then includes technical metadata of these objects in the AI request: object names, field names, data types and field lengths.
5.2 This metadata describes the structure of the customer's system, not its contents. The App reads it exclusively from Business Central's virtual metadata tables and never opens the underlying business records. No personal data contained in business records is accessed or transmitted through this mechanism.
6. Technical Operational Telemetry (Azure Application Insights)
6.1 The App emits technical operational telemetry to an Azure Application Insights resource operated by cdm-IT. This is standard Business Central publisher telemetry and is used to ensure the quality, stability and supportability of the App (for example detecting errors and compatibility issues after Business Central updates).
6.2 The telemetry is restricted by design to technical dimensions, for example:
- error and lifecycle events of the App (installation, upgrade, feature invocations);
- feature usage indicators, durations and AI token counts;
- technical context provided by the Business Central platform, such as the Microsoft Entra tenant ID, environment name and type, Business Central version and App version.
6.3 The telemetry does not include requirement contents, dialog answers, generated documents or other business data. Client IP addresses are not stored by Application Insights (Azure masks them by default). The Entra tenant ID and environment name identify the customer's organization, not individual users; the App does not add user names or user IDs to its telemetry events.
6.4 Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the secure, stable operation and improvement of the App and in fulfilling our support and maintenance obligations). Telemetry data is stored in Azure data centers in the European Union and is automatically deleted after 90 days.
7. Support Communication
7.1 If a customer contacts us for support (see cdm-it.de/appsource/ai-requirements-bridge/help), we process the contact details provided (name, business e-mail address, company) and the content of the request in order to handle it.
7.2 Legal basis: Art. 6(1)(b) GDPR (performance of a contract or steps prior to entering into a contract) and Art. 6(1)(f) GDPR (legitimate interest in handling support requests). Support correspondence is deleted when it is no longer required for the support relationship, unless statutory retention obligations require longer storage.
7.3 We recommend not including personal data of third parties or sensitive business data in support requests. Where log excerpts or screenshots are needed for analysis, please redact personal data where possible.
8. Purchase Through Microsoft AppSource
The App is purchased and billed through Microsoft Marketplace (AppSource). The data processing connected with the purchase, billing, license assignment and administration is performed by Microsoft as an independent controller under the Microsoft Privacy Statement. In the Microsoft Partner Center, cdm-IT receives from Microsoft aggregated marketplace information about its offers and, depending on the customer's choices during purchase, limited lead information (for example company name and business contact details). Such lead data is processed on the basis of Art. 6(1)(f) GDPR (legitimate interest in customer relationship management) and, where applicable, the customer's consent given to Microsoft.
9. No Other Recipients, No Third-Country Transfer by cdm-IT
cdm-IT does not sell, rent or otherwise disclose the data described in sections 6 and 7 to third parties, except where we are legally obliged to do so. Our telemetry and support systems are operated within the European Union. Any transfers within the Microsoft cloud are governed by the customer's agreement with Microsoft, including the EU Standard Contractual Clauses and the EU-US Data Privacy Framework where applicable.
10. Security
10.1 The data processed by the App is stored and processed exclusively within the Microsoft cloud infrastructure of the customer's own tenant and is protected by the security measures of the Microsoft cloud (including encryption in transit and at rest, access control and Business Central's permission model). The App adds its own permission sets so that the customer can control which users may create, edit or only read requirements and documents.
10.2 cdm-IT maintains no copy of the customer's App data, which by design eliminates the risk of a data breach at cdm-IT affecting this data. The telemetry and support data processed by cdm-IT (sections 6 and 7) is protected by appropriate technical and organizational measures, including access restriction to authorized personnel and encrypted transmission.
11. Your Rights
11.1 For personal data stored inside the customer's Business Central environment (section 3), please contact the customer (typically your employer), who is the controller for this data. cdm-IT has no access to it and cannot fulfil data subject requests concerning it.
11.2 For personal data processed by cdm-IT (sections 6–8), you have the right to:
- access (Art. 15 GDPR) to your stored data;
- rectification (Art. 16 GDPR) of inaccurate data;
- erasure (Art. 17 GDPR), subject to statutory retention obligations;
- restriction of processing (Art. 18 GDPR);
- data portability (Art. 20 GDPR);
- object (Art. 21 GDPR) to processing based on legitimate interest.
11.3 To exercise these rights, please contact: support@cdm-it.de. You also have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR); the supervisory authority responsible for cdm-IT is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen.
12. Changes to This Privacy Statement
We may amend this privacy statement when the App's data processing changes (for example when new features are added) or when legal requirements make this necessary. The current version is always available at cdm-it.de/privacy.
cdm-IT & Consulting Services GmbH — Last updated: July 2026